Fortinet black logo

Administration Guide

Setting up FortiAuthenticator as an IdP

Setting up FortiAuthenticator as an IdP
To configure general SAML IdP portal settings:
  1. Go to Authentication > SAML IdP > General and select Enable SAML Identity Provider portal.
  2. Configure the following settings:

    Setting

    Definition

    Device FQDNTo configure this setting, you must enter a Device FQDN in the System Information widget in the Dashboard.
    Server addressEnter the IP address or FQDN of the FortiAuthenticator device.
    Username input formatSelect one of the provided options. In our example, we used username@realm.
    RealmsSelect Add a realm to add the default local realm to which the users will be associated.
    Login session timeoutSet the user’s login session timeout limit to between 5 – 1440 minutes (one day). In our example, we used 500 minutes.
    Default IdP certificate

    Select a default certificate the IdP uses to sign SAML assertions from the dropdown menu.

  3. Click OK to apply these changes.
Setting up FortiAuthenticator as an IdP
To configure general SAML IdP portal settings:
  1. Go to Authentication > SAML IdP > General and select Enable SAML Identity Provider portal.
  2. Configure the following settings:

    Setting

    Definition

    Device FQDNTo configure this setting, you must enter a Device FQDN in the System Information widget in the Dashboard.
    Server addressEnter the IP address or FQDN of the FortiAuthenticator device.
    Username input formatSelect one of the provided options. In our example, we used username@realm.
    RealmsSelect Add a realm to add the default local realm to which the users will be associated.
    Login session timeoutSet the user’s login session timeout limit to between 5 – 1440 minutes (one day). In our example, we used 500 minutes.
    Default IdP certificate

    Select a default certificate the IdP uses to sign SAML assertions from the dropdown menu.

  3. Click OK to apply these changes.